ACE30 (map of setting SSL A5(3.1a))

Hi guys,.

We have an obligation to turn off support for SSLv3 and activate TLS1.0, 1.1 and 1.2 within our environment.  Since having upgraded to A5 (3.1 (a), we have at our disposal the possibility to use TLS1.0, 1.1 and 1.2 according to the release, however in practice notes, I found that there is no possibility to have only TLS1.0, 1.1, and 1.2, (not SSLv3) applied to a VIP given (via the ssl proxy controls). Tests, I found that if I want to be specific about the versions of TLS, can only be applied at the same time: for example

parameter-card type ssl SSL - TLS1.0
RSA_WITH_3DES_EDE_CBC_SHA encryption algorithm
RSA_WITH_AES_128_CBC_SHA priority 3 encryption algorithm
cipher RSA_WITH_AES_256_CBC_SHA priority 2
version TLS1

SSL-NISTEST SSL proxy service
key NISTEST-.pem
CERT NISTEST-CRT - RENEWED.pem
chaingroup SSL AUSCERTS-SERVER-STRING
SSL options advanced SSL - TLS1.0

I can't apply TLS1.0, 1.1, and 1.2, to therefore support all browsers, etc.  I tried to use "Up to TLS1.2" versions that were available, but this always includes SSLv3 which we do not want.  Cisco confirm that my observations are accurate and I can't add all 3 versions of TLS?

Thank you

Sheldon

Hi Sheldon,

You're right about the behavior, and unfortunately there is not a way to achieve what you want. I see similar requests internally here ski development. If there is no improvement application round and is decided to be implemented in the next version, I will update here.

Kind regards

Kanwal

Note: Please check if they are useful

Tags: Cisco DataCenter

Similar Questions

  • What happened to 'Ignore the map Item' application setting?

    Nobody knows what happened to applications "Ignore the map Item" setting in FDM 11.1.1.3 (Administration > Application settings)? It was the setting used to configure the value target for records to be ignored (i.e., excluded) during the import. Its default value is IGNORE. Is no longer a configurable parameter in FDM 11.1.1.3?

    My IGNORE maps still work, so I have to assume that this is always the default, but what happens if I wanted to change to something else?

    Thank you.

    If you choose to search for a member of the target in the target system returned to a list of members of the target in so that entry for 'ignore' which will be indicated as "bypass line. If something is mapped to ignore all of the record source line is bypassed.

    Hope that answers the question.

  • Router WAN double with SSL VPN inaccessible for customers

    I have a configured in a Dual WAN setup Cisco 888. There is an ADSL link connected to the VLAN 100 and a SDSL link associated with the Dialer0. The customer wishes to use the ADSL link to the normal navigation and external SSL VPN users to complete on the SDSL connection. I tried to configure the link failover for the ADSL SDSL.

    What works:

    -Access to the Internet for clients the

    What does not work:

    -The ADSL SDSL connection failover.

    -Access SSL VPN for customers. Surf to the external IP address will cause only a page by default HTTP. Specification webvpn.html results in a 404 not found error.

    Here is my configuration:

    version 15.0

    no service button

    horodateurs service debug datetime msec

    Log service timestamps datetime msec

    no password encryption service

    !

    host name x

    !

    boot-start-marker

    boot-end-marker

    !

    logging buffered 51200 warnings

    enable secret 5 x

    !

    AAA new-model

    !

    !

    AAA authentication login local sslvpn

    !

    !

    !

    !

    !

    AAA - the id of the joint session

    iomem 10 memory size

    !

    Crypto pki trustpoint TP-self-signed-3964912732

    enrollment selfsigned

    name of the object cn = IOS - Self - signed - certificate - 3964912732

    revocation checking no

    rsakeypair TP-self-signed-3964912732

    !

    !

    TP-self-signed-3964912732 crypto pki certificate chain

    self-signed certificate 03

    x

    quit smoking

    IP source-route

    !

    !

    IP dhcp excluded-address 192.168.10.254

    DHCP excluded-address IP 192.168.10.10 192.168.10.20

    !

    DHCP IP CCP-pool

    import all

    network 192.168.10.0 255.255.255.0

    default router 192.168.10.254

    DNS-server 213.75.63.36 213.75.63.70

    Rental 2 0

    !

    !

    IP cef

    no ip domain search

    property intellectual name x

    No ipv6 cef

    !

    !

    udi pid CISCO888-K9 sn x license

    !

    !

    username secret privilege 15 ciscoadmin 5 x

    username password vpnuser 0 x

    !

    !

    LAN controller 0

    atm mode

    Annex symmetrical shdsl DSL-mode B

    !

    interface Loopback1

    Gateway SSL dhcp pool address description

    IP 192.168.250.1 255.255.255.0

    !

    interface Loopback2

    Description address IP VPN SSL

    IP 10.10.10.1 255.255.255.0

    route PBR_SSL card intellectual property policy

    !

    interface BRI0

    no ip address

    encapsulation hdlc

    Shutdown

    Multidrop ISDN endpoint

    !

    ATM0 interface

    no ip address

    load-interval 30

    No atm ilmi-keepalive

    PVC KPN 2/32

    aal5mux encapsulation ppp Dialer

    Dialer pool-member 1

    !

    !

    interface FastEthernet0

    switchport access vlan 100

    !

    interface FastEthernet1

    !

    interface FastEthernet2

    !

    interface FastEthernet3

    !

    interface Vlan1

    LAN description

    IP address 192.168.10.254 255.255.255.0

    IP nat inside

    IP virtual-reassembly

    IP tcp adjust-mss 1300

    !

    interface Vlan100

    Description KPN ADSL 20/1

    DHCP IP address

    NAT outside IP

    IP virtual-reassembly

    !

    interface Dialer0

    Description KPN SDSL 2/2

    the negotiated IP address

    IP access-group INTERNET_ACL in

    NAT outside IP

    IP virtual-reassembly

    encapsulation ppp

    Dialer pool 1

    Dialer-Group 1

    PPP pap sent-username password 0 x x

    No cdp enable

    !

    IP local pool sslvpnpool 192.168.250.2 192.168.250.100

    IP forward-Protocol ND

    IP http server

    local IP http authentication

    IP http secure server

    IP http timeout policy slowed down 60 life 86400 request 10000

    !

    pool nat SSLVPN SDSL 10.10.10.1 IP 10.10.10.1 netmask 255.255.255.0

    IP nat inside source static tcp 10.10.10.1 443 interface Dialer0 443

    IP nat inside source static tcp 10.10.10.1 80 Dialer0 80 interface

    IP nat inside source overload map route NAT_ADSL Vlan100 interface

    IP nat inside source overload map route NAT_SDSL pool SSLVPN SDSL

    IP route 0.0.0.0 0.0.0.0 x.x.x.x

    IP route 0.0.0.0 0.0.0.0 Dialer0 10

    !

    INTERNET_ACL extended IP access list

    Note: used with CBAC

    allow all all unreachable icmp

    allow icmp all a package-too-big

    allow icmp all once exceed

    allow any host 92.64.32.169 eq 443 tcp www

    deny ip any any newspaper

    Extended access LAN IP-list

    permit ip 192.168.10.0 0.0.0.255 any

    refuse an entire ip

    !

    Dialer-list 1 ip protocol allow

    not run cdp

    !

    !

    !

    !

    NAT_SDSL allowed 10 route map

    match the LAN ip address

    match interface Dialer0

    !

    NAT_ADSL allowed 10 route map

    match the LAN ip address

    match interface Vlan100

    !

    PBR_SSL allowed 10 route map

    set interface Dialer0

    !

    !

    control plan

    !

    !

    Line con 0

    no activation of the modem

    line to 0

    line vty 0 4

    privilege level 15

    transport input telnet ssh

    !

    max-task-time 5000 Planner

    !

    WebVPN MyGateway gateway

    hostname d0c

    IP address 10.10.10.1 port 443

    redirect http port 80

    SSL trustpoint TP-self-signed-3964912732

    development

    !

    WebVPN install svc flash:/webvpn/anyconnect-dart-win-2.5.0217-k9.pkg sequence 1

    !

    WebVPN install svc flash:/webvpn/anyconnect-macosx-i386-2.5.0217-k9.pkg sequence 2

    !

    WebVPN install svc flash:/webvpn/anyconnect-macosx-powerpc-2.5.0217-k9.pkg sequence 3

    !

    WebVPN context SecureMeContext

    title "SSL VPN Service"

    secondary-color #C0C0C0

    title-color #808080

    SSL authentication check all

    !

    login message "VPN".

    !

    Group Policy MyDefaultPolicy

    functions compatible svc

    SVC-pool of addresses "sslvpnpool."

    SVC Dungeon-client-installed

    Group Policy - by default-MyDefaultPolicy

    AAA authentication list sslvpn

    Gateway MyGateway

    development

    !

    end

    Any suggestions on where to look?

    Hello

    It works for me. When the client tries to resolve the fqdn for the domain specified in "svc split dns.." he will contact the DNS server assigned through the Tunnel. For all other questions, he contacts the DNS outside the Tunnel.

    You can run a capture of packets on the physical interface on the Client to see the query DNS leaving?

    Also in some routers, DNS is designated as the router itself (who is usually address 192.168.X.X), if you want to make sure that assigned DNS server doesn't not part of the Split Tunnel.

    Naman

  • Attribute LDAP AnyConnect Map

    I'm trying to configure the attribute map for our SSL Anyconnect Client connections. Basically I want all connections to be deleted, unless the AD attribute numbering is set to allow users.

    I have it working. But according to the instructions of Cisco, you create a group policy for NoAccess as your default strategy for your connection profile and kinematics-connections set to 0. The idea being to all connections will be dropped unless they use a different group strategy. As soon as I change my strategy of group - by default-NoAccess, I can not connect.

    ldap attribute-map LDAPVPN
      map-name  msNPAllowDialin IETF-Radius-Class
      map-value msNPAllowDialin FALSE NOACCESS
      map-value msNPAllowDialin TRUE SSL-VPN

    aaa-server LDAP protocol ldap
    aaa-server LDAP (inside) host 192.200.202.5
    server-port 389
    ldap-base-dn dc=*****,dc=com
    ldap-scope subtree
    ldap-naming-attribute sAMAccountName
    ldap-login-password *****
    ldap-login-dn CN=cisco,OU=Service,OU=Accounts,OU=*****,DC=******,DC=com
    server-type microsoft
    ldap-attribute-map LDAPVPN

    group-policy SSL-VPN internal
    group-policy SSL-VPN attributes
    dns-server value 192.200.202.5 192.200.202.6
    vpn-tunnel-protocol svc
    split-tunnel-policy tunnelspecified
    split-tunnel-network-list value VPN-Tunnel
    group-policy NoAccess internal
    group-policy NoAccess attributes
    vpn-simultaneous-logins 0
    vpn-tunnel-protocol IPSec svc
    webvpn
      svc ask none default svc

    tunnel-group SSL-VPN type remote-access
    tunnel-group SSL-VPN general-attributes
    address-pool ssl-pool
    authentication-server-group LDAP
    default-group-policy NoAccess
    tunnel-group SSL-VPN webvpn-attributes
    group-alias ******* enable

     If I check debug you can see the attribute being mapped correctly. What gives?

    test aaa authorization LDAP host 192.200.202.5 username ****

    [333]   msNPAllowDialin: value = TRUE
    [333]           mapped to IETF-Radius-Class: value = SSL-VPN
    [333]           mapped to LDAP-Class: value = SSL-VPN

     

    Hello, please follow these steps:

    attributes of SSL - VPN group policy

    VPN - connections 3

    What is happening here is that the SSL - VPN group policy inherits the value 0 of concurrent vpn connections to NoAccess policy as soon as set you it uo as default group policy under the tunnel-group. That's why we need to specifically add value on SSL - VPN group policy.

  • Windows Explorer stops working when I try to access a drive mapped on my FTP server on the internet.

    I just changed web pages (using Crimson editor) and instead to save the files on my hard drive I just left open and "hibernating" my machine overnight.  After 3 days of having an FTP connection (opened by a mapped drive) setting on my computer hibernation, I accidentally hit Shut Down, and I lost all my work, ARGH! (Yes, I know, I should have better). In any case, now when I open my computer and click on the FTP of the mapped drives, I get the message that Windows Explorer has stopped working.  And if I go to Internet explorer (7), enter ' ftp://mysite.com it brings me to a root FTP page where it says: to view this FTP site in Windows Explorer, click Page, and then click Open the FTP Site in Windows Explorer. " I do that and it brings up a window of the Explorer windows momentarily and then I get the message. Explorer Windows has stopped working.  Any ideas? I hope I don't have to reinstall the operating system.  I did a system restore to 4 days ago. It did not work.

    Hi SewNSew,

    To refine the question, I suggest you try the following steps:

    Step 1: Set the clean boot computer and try to access the drive

    Follow step 1 in the link below,

    How to troubleshoot a problem by performing a clean boot in Windows Vista or in Windows 7

    http://support.Microsoft.com/kb/929135

    If everything works well after a clean boot, you can deduce that some third-party services are at the origin of the problem.

    After find you the program that is causing the problem, you will have to perhaps to update or install a newer version of the program, if you rarely use that you should consider uninstalling the software

    Important: n ' forget not the computer to start normal follow step 7 in the link

    Step 2: The utility of Auditor (SFC) for the file system allows administrators to perform an analysis of all protected resources to make sure they are the correct version. Whether SFC should find all incorrect versions in one of these protected resources, SFC will be replaced by the correct versions.

    You can still run a SFC scan on the windows vista computer. To run a scan suite SFC as follows:

    (a) click Start and in the start search bar type cmd, right-click on the command prompt icon in the box programs and then click Run as administrator.

    (b) at the command prompt type sfc/scannow , and then press ENTER.

    If the problem persists,

    Step 3: Disable control (UAC) user account and make sure to do this, follow these steps:

    1. open user accounts by clicking the Start button, clicking Control Panel, click user accounts and family safety (or by clicking on user accounts, if you are connected to a network domain), and then clicking user accounts.

    2. click on Turn User Account Control on or off.  If you are prompted for an administrator password or a confirmation, type the password or provide confirmation.

    3. Select the use User Account Control (UAC) to help protect your computer, clear the check box to disable UAC, and then click OK.

    Important: It is not recommended to disable UAC; We just try to limit the question. Please, enable UAC after the test is performed. See the link below:

    http://Windows.Microsoft.com/en-us/Windows-Vista/turn-user-account-control-on-or-off

    See the link below for more information

    Error message when you log on to Windows Vista: "Windows Explorer has stopped working".

    http://support.Microsoft.com/kb/937093

    Thank you, and in what concerns:

    Ajay K

    Microsoft Answers Support Engineer

    Visit our Microsoft answers feedback Forum and let us know what you think.

  • CIsco first Heat Map influence APs?

    Hi all

    I never thought, but after a discussion, I'm not sure and would like to check that.

    Today, I thought that if I add a few APs for cards wireless with influence to their function. But another person that I talked about last week: it is very important to the excact cards have the APs function correctly.

    So for example I add two APs in a map and set very close to 5 meters. In real time, they are 30 meters apart. If the first will tell the WLC to move down the power level? or something like that.

    for example if the height is not correct or would that hurt?

    In conclusion, how much is the precise card has an influence on the function of the AP? For me, it was just a tool to view now.

    Thank you!

    Best regards
    Sebastian

    Hey, Sebastian,.

    I used to think the same thing, but the short answer is no, ICC Heatmaps do not influence AP behavior in some way, they're watching purely based on data sent back to the tool.

    See you soon,.

    Ric

  • Config map crypto

    I would like to know if we can configure several cryptographic cards on a single interface?

    Hello

    You cannot use more than one card encryption on an interface, but you can use separate entries within the same encryption card IE.

    map vpn - set 1 iskamp ipsec crypto

    vpn - set 1 set x.x.x.12 counterpart crypto card

    ...

    Your next VPN would be

    map vpn - set 2 ipsec-isakmp crypto

    card crypto vpn - set set peer y.y.y.15

    etc.

    HTH

    Jon

  • Sharing mapped network can not access Windows7

    I have a lab of 30 computers, on one of the pc I have a strange problem on that then any network user connects, the mapped drive appears well, but when they try and access the shared drive, they get an error of location is not available.

    When users try and manually browse to the network share I get a network error - you are not allowed to access the share.
    I'm quite sure this isn't a permissions problem or users would not be able to access the same share the other 29 computers.
    I have an another two mapped drives, set up that work very well, it is just this action on this computer, (disks are mapped via Group Policy on the server 2008r2)
    I disconnected the mapped drive re-connected, took the computer out of the domain and dns reconnected, checked, discovery of the network, group policy settings, share permissions... all seem well
    Any help advise would be greatly appreciated!

    Hello

    Your linked windows question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public.

    Please post your question in the TechNet Support.

    http://social.technet.Microsoft.com/forums/en-us/w7itpronetworking/threads

    It will be useful.

  • How can I culture a map in MapPoint or

    How can I culture a map in MapPoint or?  I need just to a map of Wisconsin, and MapPoint only allows me to zoom / zoom out.  I want to be able to show just Wisconsin.  Make the territories does not work because it makes the territory and do not crop the map we set.  In addition, how can I reframe certain counties so that it is just the counties I work with are on the map?  MapPoint help is very poor!

    There is an excellent complement MapPoint: MapPoint IC-ShapeManager.
    Take a look at the Manual. You can download the tool.

    Kind regards
    Manfred Sundorf

    PROFIT100 Consulting, Germany
    http://www.profit100.EU

  • Mapping and querying objects for Contact with REST Api

    Hi all

    We are hoping to get some details on the DataCard management defined via REST API. Our implementation goal is to create Contacts and add the custom for each Contact object or to be more precise, add a set of map data for each Contact.

    At the present time, to associate a map Data Set (or custom object) to an existing contact, we provide a suite of fields in the custom when creating custom object object:

    new CustomObjectField  
    {
                                                                    name = "MappedEntityType",
                                                                    dataType = Enum.GetName(typeof(DataType), DataType.numeric),
                                                                    type = "CustomObjectField",
                                                                    defaultValue = "0"
                                                                },
                                                             new CustomObjectField
                                                                {
                                                                    name = "MappedEntityID",
                                                                    dataType = Enum.GetName(typeof(DataType), DataType.numeric),
                                                                    type = "CustomObjectField",
                                                                    defaultValue = "<ContactId>"
                                                                }
    
    

    This is the right approach? This is based on the information provided here: http://topliners.eloqua.com/community/code_it/blog/2012/05/31/eloqua-api-how-to-mapping-a-data-card-to-an-entity.

    The REST API would query the CustomObjects using the MappedEntityId value for the subsequent updates? If so, pointers on how to approach that?

    Thanks to ad.

    The REST API does not support this.  With the upcoming release of Eloqua, you will be able to update the MappedEntityID, as a query it.

  • Setting up automatic sync?

    We have several clocks automatic put in place under the installation/integration program that capture the csv files, placed on a sftp server that publish data in the files of data cards. The person who created these has left and I want to put in place more, but I can't for the life of understand me how to add new ones. Can anyone help?

    Thank you.

    Hi Rob,

    Go to the map data set that is created, or a new set of data card that you created.  Prepare a file to download map of dummy data, then under the Data Card Set options drop-down, select download data cards (use your dummy file to download).  In the first step of the wizard, select the type of download file on FTP, or another type that you have created (if necessary, you can create a different type of data card by clicking on configure > integration > incoming > create data sources and create a new data source - the main reason you do it is that the priority for downloading list).

    Once you select file on FTP or your other source, you will be asked to provide identification information SFTP (SFTP address, username, password). Fill out the fields with your information and continue the process.  If successful, before you complete the wizard, SAVE YOUR SETTINGS to UPLOAD.  Everything that you name the 'save the download settings' will be the name of your Auto Synch.

    Once you have finished downloading, and you saved your download settings, you will see your automatic synchronization.  You can then adjust your automatic synchronization settings.

    If all goes well, that will work for you!

    Vince

  • OMBPlus report definition syntax "rule action" on a data_rule in a map

    Hello

    I'm trying to make sure that all the rules given in the tables of my maps are set to 'REPORT' and want to use OMBPlus for this but I can't find the proper syntax to do this. This is what seems logical to me at this time to retrieve the current value:

    OMBRETRIEVE MAPPING '$mapName' DATA_RULE '$ruleName' OPERATOR '$tbl' GET PROPERTIES (RULE_ACTION)

    It makes me:

    OMB02933: Error getting child object of the type DATA_RULE with 1855 name: MMM1034: DATA_RULE property does not exist.

    I also tried the reverse:

    OMBRETRIEVE MAPPING '$mapName' OPERATOR '$tbl' DATA_RULE '$ruleName' GET PROPERTIES (RULE_ACTION)


    also gives an error.


    Does anyone know the correct syntax?


    Thank you

    Eric.

    To answer my own question and anyone else looking for the correct syntax, this is what I came with:

    # some variables for name mapping ($mapName) settings and scoreboard operator target ($tgttbl) in the mapping took place before these lines

    define the rules [OMBRETRIEVE '$mapName' OPERATOR '$tgttbl' DATA_RULES GET from MAPPING]

    foreach rule $rules {}

    OMBRETRIEVE MAPPING '$mapName' OPERATOR '$tgttbl' DATA_RULES '$rule' GET PROPERTIES (RULE_ACTION)

    MAPPING of the OMBALTER '$mapName' CHANGE the VALUES of PROPERTIES (RULE_ACTION) DATA_RULES '$rule' OPERATOR '$tgttbl"("REPORT")

    }

    REPORT can be replaced by IGNORE or BR_MOVE_TO_ERROR, according to the necessary RULE_ACTION.

  • Output of mapping a custom BPM object DB adapter

    Hello
    I'm trying to map a set of my Adapater DB to a custom BPM object. My DB adapter contains a sql select statement that returns multiple order records. I want this card to my "orders" defined in the BPM project. I saw the new transformation Editor, but I don't know what choice do the mapping.

    Thank you.

    If you select "Use the Transformations" as type of data binding, which will have you use/create a xsl to do the transformation. In the Visual editor for XSL JDev, if you drag the type returned to your type I think we need to create a and create maps of specific fields.

  • paths of folers updated - maps?

    Hello

    I already use maps to set the location of my CFC. In my file of the Application, I tend to use folders file like this

    < cfset application.galleryPath = "/ MySite/Gallery/galleryImages /" >

    and use #application.galleryPath # when display my images.

    Now, on my remote server I can set a maps on a site-by-site basis

    /galleryImages/httpdocs/backend/galleryImages

    but locally because I create and test several sites I have to do with the name of the site

    /site1galleryImages/httpdocs/site1/backend/galleryImages

    /site2galleryImages/httpdocs/site2/backend/galleryImage

    which means finally that I have hundreds of maps. Is there a solution?

    If not what do I do with the variables of the apllication ok or someone at - it an alternative?

    Thank you.

    Hulfy,

    On your local development box, you can create virtual servers for each site that you are working to keep things clean and separate while developing.

    I'm on Mac 10.5.7 with Apache 2.2.9 and ColdFusion 8.0.1. That's what I do when I start a new project or site:

    1. in my hosts file (/ private/etc/hosts), I add a new entry to the host for my site I'm starting a new project:

    127.0.0.1 dev.mynewsite.local

    On Windows, this same (hosts) file is in general here:windows\system32\drivers\etc\hosts c:\

    2. in my Apache httpd - vhosts.conf, I add a virtual server to this new site entry:

    
          ServerName dev.mynewsite.local
          ServerAlias dev.mynewsite.local
          ServerAdmin [email protected]
          DirectoryIndex index.cfm index.html index.htm
          DocumentRoot /Users/path/to/Sites/mynewsite
       
    

    I think that in IIS, you create a site in IIS right and say Administrator site to 'listen' to the requests from the host/domain created in step 1, above.

    3. I have restart Apache (I don't think that IIS must restart for this) & I'm ready to go.

    If I indicate my http://dev.mynewsite.localbrowser, I see my new site setup. Now I can put my maps just as I do on the production server and without worrying about the mappings duplicated, assuming that your new application has its own file of Application (cfm or CFC). I find that with this configuration and the approach, I can better mirror or mimic my production environment when I develop, more it keeps all my sites/projects local clean and tidy!

    Regarding the use of the scope, I think that it is somewhat a greater "debate". Personally, I like this scope for the objects used in the world, common elements such as DSN, mappings and similar. I'm just not trying to go to sea and push too much into it.

  • Attributes not mapped with more of OMB getting

    Hi all

    I'm trying to find out how to get a list of the attributes of an operator, that are not mapped.
    In the user interface, is to select the display to "cancelled".

    Thank you!
    Kind regards
    Sebastian

    Hi Sebastian,.

    Modify the script according to your needs:

    set map "MAP_TEST"
    set target "DIM_DEMO"
    set targetGroup "INOUTGRP1" 
    
    set attributeList [OMBRETRIEVE MAPPING '$map' OPERATOR '$target' GROUP '$targetGroup'  GET ATTRIBUTES]
    foreach attribute $attributeList {
         set operatorList [ OMBRETRIEVE MAPPING '$map' GET OPERATORS CONNECTED TO ATTRIBUTE '$attribute' OF GROUP '$targetGroup' OF OPERATOR '$target' ]
         if {[string length $operatorList] < 1 } {
              puts "$attribute has no IN connection"
         }
    }
    
    foreach attribute $attributeList {
         set operatorList [ OMBRETRIEVE MAPPING '$map' GET OPERATORS CONNECTED FROM ATTRIBUTE '$attribute' OF GROUP '$targetGroup' OF OPERATOR '$target' ]
         if {[string length $operatorList] < 1 } {
              puts "$attribute has no OUT connection"
         }
    }
    

    The first loop is looking for about, the second loop looks for matches.

    Kind regards
    Carsten.

Maybe you are looking for